Telegram moves to protect identity of Hong Kong protesters
reuters.com
reuters.com
> A phone number used by [Telegram] account @silovikicat was discovered using a program titled "Insider-Telegram" developed by the "Center of research of legitimacy and political protest". The head of the "Center" Eugene Venediktov explains: "Currently the database contains over 10 million of numbers. We just go through all possible numbers and check whether they are registered in Telegram: for example, we take all numbers starting with a prefix +7911 and check them. You automatically see all contacts from you address book in your Telegram, don't you? We just have a very "fat" address book with phones of all users from our country."
> When a phone number provided by Eugene is added into an address book, Telegram automatically matches it with account @silovikicat («Siloviks' cat»).
Having a phone number means that the government can track its rough location and know owner's identity.
This also means that other messengers using similar contact discovery allow to de-anonymize its users the same way.
[1] (in Russian) https://meduza.io/feature/2019/08/10/kto-takoy-tovarisch-may...
It’s just like Venmo. I’m seeing users in my newsfeed because they’re in my contacts but not because we added each other. Really bizarre.
I guess what they'll do instead is to just outlaw Telegram :-|
- fighting someone who controls Stripe well enough to browse transaction logs
- or you are fighting someone who can access your bank transactions (more likely in this case) and manage to correlate them correctly with Telegram account creation time
Both seems like huge steps forward compared to sms validation.
Furthermore: Bitcoin is not much safer for the ordinary citizen. If anything it is way easier to trace than cash and I guess slightly more different to trace than bank transfers.
Or am I missing something?
While I don't like to have messaging apps tied to the phone number, it has become a mainstream model that most people accept and know how to use.
I have been thinking for some time that we need a mainstream messaging app that uses end-to-end encrypted, and you can get in contact with a peer only if it accepts you (just like old messaging apps, WLM, ICQ, etc), so, if the peer doesn't accept to chat with you, you won't even know whether the number is registered.
In fact, my initial PoC is https://safer.chat/, I just need the time to make an app from it.
> Telegram hopes to help protect Hong Kong protesters with the update, the source said. But wide adoption of the optional security setting would make the app far harder to use for the vast majority of its more than 200 consumers, who rely on uploading phone contacts to identify friends and family members on the app, the source said.
Make the match 2 way then.
If you both have reach other's number allow the match. If it's one sided - deny.
> The app automatically matches phone numbers with the user names in the group. Chinese authorities then only need to request the owners of the phone numbers from the local telecom service in order to learn the users’ true identities.
> Telegram has detected evidence that Chinese authorities may have uploaded numbers to identify protesters, said a person with direct knowledge of the situation.
Signal does/did this too: https://news.ycombinator.com/item?id=12590979
This is a flaw common to services that rely on phone numbers as IDs. In many countries, one cannot purchase a SIM card without showing ID (and the seller makes a photocopy of the ID to provide to the authorities). That means that there cannot be true anonymity. Know the phone number, know the person.
I am always baffled when people claim that PGP-encrypted e-mail is passé because it leaks metadata, when Signal and Telegram leak metadata too and, furthermore, metadata that can be immediately associated with a specific person in many countries.
It is dangerous to use such messengers like Signal (or Telegram) with a real phone number.
Which I've done personally for many years. They won't tell you it's possible at the stores but they don't ask questions if you say you forgot your drivers licence at home.
Fortunately that's not the only identity separation you can create, which IMO is as or more important day to day than encryption and other technical solutions.
But nothing beats limiting government power through policy which seems to unpopular these last few decades.
The problem is this would both a) need to be used by Signal as the primary number ID b) your friend would need to know this separate number just for chat (unless you also use it for calls and other stuff then no biggie)
Of course this also kills new friend discovery, which is probably not needed by most.
I haven't tried using SIP on my phone app while simultaneously having a SIM number so I'm not sure Signal can be routed through an arbitrary number on your phone. But I could be wrong. Maybe someone else knows?
Here in New Zealand, I can freely purchase any prepay SIM without ID and use it straight away. Most, if not all dairies carry them too.
You can even purchase cards without ID that also work in Mainland China and aren't subject to the great firewall.
NZ is obviously loose due to large number of tourists, I reckon. So easy to get SIM cards, I've got 2 (spark and 2 degrees). US also requires ID to get SIM last time I was in bay area (2016).
Pretty sure they all do. I've used prepaid on all the major carriers and bigger MVNOs and I needed to give some form of ID to the signup process.
In Germany you now apparently need to show ID and provide an address, though no proof of residence so any address seems acceptable.
Isn't there a secure messaging app that doesn't require a phone number and doesn't ask me to upload my contacts?
*Untrue. See comments below.
If they were selling the HK protestors out to the Chinese government they would also say this.
True trustworthyness can only come from open source code and concepts designed into the protocol. I don't think this can be achieved on Apple's platform, might be possible on Android.
Smart contract enables the true transparent and honest program but the technology is not ready yet. It is still early days.
Everything you said about open-source applies to Android too. At the very least all kinds of backdoors are in Android phone because of chip firmware. But I guess you might be alluding to the fact that Tim Cook handed over Apple iCloud keys to the Chinese govt.
This is not a general proclamation.
Especially on Google platform with every click tracking.
This is false: regardless of Telegram’s nags to upload my phone book to them, I find it quite easy to use the app without doing this.
I will never understand why apps that profess allegiance to privacy upload entire contact lists.
Sure, users will complain it’s harder. They’ll always complain, but you’re protecting them and their contacts who have NOT provided consent.
Btw why all these apps require a phone #? Is it required by the gov?
End-to-end encryption only works in "secret chats" and voice calls. Outside of those, it's as encrypted as HN is (connection happens over TLS, but that's about it).
IMO phone numbers are a pretty terrible system (you would never ask people to remember dozens of IP addresses for all the websites they want to visit but historically people have been expected to remember phone #s for all the people they want to contact), but they are the system we have and it could be worse.
With only 200 users on the app me thinks adoption will be fast - think they forgot a “K”
an "M" - 200 million users as of March 2018. https://telegram.org/blog/200-million
It is terribly unlikely that they’d have their users best interest in mind.